A Site-to-Site VPN to a branch office terminates on a transit gateway and uses static routes. The transit gateway route table contains many static routes that point to specific branch-office subnets. The branch office later expands its subnet ranges and connectivity fails. Which approach minimizes future administrative work while addressing this issue?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a dynamically routed VPN connection on the transit gateway. Connect the dynamically routed VPN connection to the branch office. Create a propagation for the VPN attachment to the transit gateway route table. Remove the existing static VPN connection..
Why this is the answer
The correct option automates route updates, minimizing future administrative work. Dynamically routed VPNs (using BGP) allow the branch office router to advertise its routes to the Transit Gateway, which then automatically updates its route table via propagation. This eliminates the need for manual route updates when branch office subnets change. The supernet option requires manual updates whenever the branch office subnet ranges expand beyond the defined supernet, or if they become more granular. Direct Connect is a separate connectivity solution and doesn't directly address the dynamic routing need for a VPN. Prefix lists are used for route filtering and aggregation, but still require manual updates to the prefix list itself when subnets change, and the Transit Gateway route table still needs to be updated to reference the new prefix list.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed